Threat Overview
On October 1, 2026, the Symantec and Carbon Black Threat Hunter Team reported ongoing intrusions by Longlegs, the China-nexus actor also tracked as Warlock, Storm-2603, and Gold Salem. During the preceding two months, the actor attacked at least four organizations—including a water utility, telecommunications provider, regional government body, and university—across Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America.
The observed chain began with likely exploitation of on-premises Microsoft SharePoint Server and an ASPX web shell in a SharePoint LAYOUTS directory. The actor then performed domain reconnaissance, used DLL side-loading, fetched MSI payloads from public cloud/file-sharing services, created covert VS Code tunnels, used NetExec for spraying and remote execution, deployed an AV/EDR-killing tool using a vulnerable signed K7RKScan driver (CVE-2025-1055), and staged ransomware in SYSVOL for domain-wide replication. In one incident, the security-disabling tool reached at least 40 hosts in roughly two hours and Warlock ransomware reached at least 33.
The intrusion activity and artifacts below are researcher-observed facts. The initial vector in the detailed July 22 case is assessed as likely SharePoint exploitation; reporting indicates ToolShell and other SharePoint flaws remain viable, but does not attribute every recent intrusion to one exact CVE.
References
- Symantec and Carbon Black Threat Hunter Team, “Warlock Ransomware Attackers Hit Water and Telecom Operators,” published October 1, 2026: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
- The Hacker News, “Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware,” published October 3, 2026: https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
- BleepingComputer, “Warlock ransomware breaches SharePoint in water, telecom operator attacks,” published October 2, 2026: https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
Impacted Systems
- Initial-access platform: On-premises Microsoft SharePoint Server; reporting does not identify a single affected version for every incident.
- Known vulnerability context: ToolShell chain CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, plus potentially newer SharePoint flaws. Exact CVE use in the detailed July 2026 intrusion is not confirmed.
- Operating system/roles: Windows SharePoint servers, Active Directory domain controllers, and domain-joined Windows endpoints/servers.
- Prerequisite/exposure: A reachable vulnerable SharePoint deployment; Internet-facing on-premises servers have the highest initial-access risk.
- Post-compromise dependencies: Domain credentials/privileges sufficient for lateral movement and SYSVOL staging; vulnerable K7RKScan driver for the observed BYOVD security-tool disablement.
- Not in scope: SharePoint Online is not reported as the exploited server platform in this campaign.
- Fixed versions: Apply Microsoft’s current SharePoint security updates for the exact supported product line; this campaign report does not provide one universal fixed build.
Why this matters
This is confirmed, recent ransomware activity against critical infrastructure and public-sector/education targets, using an Internet-facing enterprise server for initial access and domain-native replication for rapid scale. The chain provides multiple high-fidelity Sentinel opportunities before encryption: IIS worker child processes, web-shell creation, MSI downloads, VS Code tunnel installation, local-admin changes, EDR-killer deployment, and SYSVOL staging.
Exploitation Status
Confirmed active threat activity. Symantec/Carbon Black observed at least four recent victims and documented an intrusion beginning July 22, 2026. SharePoint exploitation is assessed as the likely initial vector. The actor’s observed sequence, filenames, hashes, domains, and commands are confirmed researcher telemetry; continued use of every artifact should not be assumed.
What this hunt looks for
Published hashes, SharePoint worker child processes, ASPX writes in LAYOUTS, observed side-loading files, public-hosting callbacks, VS Code tunnel installation, local-administrator changes, SYSVOL staging, and rapid security-tool suppression across hosts.
Required logs
Microsoft Defender for Endpoint DeviceProcessEvents, DeviceFileEvents, and DeviceNetworkEvents on SharePoint servers, domain controllers, and endpoints; Windows Security Events with command-line auditing; IIS/WAF logs; and DNS, proxy, or firewall telemetry.
Hunt 1 — Published Warlock, DLL, driver, and EDR-killer hashes
let lookback = 90d;
let hashes = dynamic([
"116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c","155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55",
"1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60","206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261",
"27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0","37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e",
"6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad","73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea",
"8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f","8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9",
"9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7","aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192",
"ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295","c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e",
"e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20","e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1",
"eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed","f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf",
"fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984"]);
union isfuzzy=true
(DeviceFileEvents | where Timestamp >= ago(lookback) | project EventTime=Timestamp, DeviceName, ActionType, FileName, FolderPath, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine),
(DeviceProcessEvents | where Timestamp >= ago(lookback) | project EventTime=Timestamp, DeviceName, ActionType, FileName, FolderPath, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine)
| where SHA256 in~ (hashes)
| order by EventTime desc
Hunt 2 — SharePoint worker spawning shells, discovery, or installers
let lookback = 90d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName in~ ("w3wp.exe", "OWSTIMER.EXE", "Microsoft.SharePoint.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "msiexec.exe", "rundll32.exe", "regsvr32.exe", "net.exe", "nltest.exe", "whoami.exe")
or ProcessCommandLine has_any ("FromBase64String", "System.Workflow.ComponentModel", "Invoke-WebRequest", "net user /domain", "domain_trusts")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
| order by Timestamp desc
Hunt 3 — ASPX creation in SharePoint LAYOUTS paths
let lookback = 90d;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where FolderPath has @"\Microsoft Shared\Web Server Extensions\"
| where FolderPath has @"\TEMPLATE\LAYOUTS\" and FileName endswith ".aspx"
| where ActionType in~ ("FileCreated", "FileModified", "FileRenamed")
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessAccountName
| order by Timestamp desc
Hunt 4 — Observed side-loading and staging filenames
let lookback = 90d;
let names = dynamic(["layout2sp.aspx", "doexeloc.dll", "doexeloc.dll.tmp", "doexe.exe", "ssvagent.exe", "logger.exe", "gsdll64.dll.tmp", "a.exe", "nxc.exe", "run.exe", "rune.exe"]);
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where FileName in~ (names)
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, FileOriginUrl, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Hunt 5 — Downloads or callbacks to observed public-hosting infrastructure
let lookback = 90d;
let domains = dynamic(["litter.catbox.moe", "s3.wasabisys.com", "xn8xyt-drop.s3.wasabisys.com"]);
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where RemoteUrl in~ (domains) or RemoteUrl endswith ".oastify.com"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, LocalIP
| order by Timestamp desc
Hunt 6 — VS Code tunnel installed as a service
let lookback = 90d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("code.exe", "code-insiders.exe")
| where ProcessCommandLine has_all ("tunnel", "service", "install") or ProcessCommandLine has "--accept-server-license-terms"
| project Timestamp, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Hunt 7 — Local Administrators additions and campaign masquerading account
let lookback = 90d;
SecurityEvent
| where TimeGenerated >= ago(lookback)
| where EventID == 4732
| where TargetUserName =~ "Administrators" or TargetSid endswith "-544"
| where MemberName has "SPSEPRDSetup" or Account has "SPSEPRDSetup" or Activity has "SPSEPRDSetup"
| project TimeGenerated, Computer, SubjectAccount, MemberName, MemberSid, TargetUserName, Activity
| order by TimeGenerated desc
Hunt 8 — SYSVOL payload staging or DFSR-delivered executables
let lookback = 90d;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where FolderPath has @"\SYSVOL\" and FileName matches regex @"(?i)\.(exe|dll|ps1|bat|cmd|msi)$"
| where ActionType in~ ("FileCreated", "FileModified", "FileRenamed")
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessAccountName
| order by Timestamp desc
Hunt 9 — Security-tool termination, vulnerable-driver staging, and rapid fan-out
let lookback = 90d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("taskkill.exe", "sc.exe", "net.exe", "cmd.exe", "powershell.exe", "a.exe")
| where ProcessCommandLine has_any ("stop", "delete", "taskkill", "K7RKScan", @"\users\public\a.exe", @"\av\*")
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Devices=dcount(DeviceName), DeviceList=make_set(DeviceName, 100), Commands=make_set(ProcessCommandLine, 20) by InitiatingProcessAccountName, FileName, bin(Timestamp, 2h)
| where Devices >= 3 or Commands has_any ("K7RKScan", @"\users\public\a.exe")
| order by FirstSeen desc
Detection Notes
- Hunts 1, 3, 5, and 6 are the highest-signal checks because they use published artifacts or highly unusual behaviors. Historical IOCs can be repurposed or inactive; validate event time and context.
- SharePoint worker child processes are rarely expected to launch shells, reconnaissance tools, or
msiexec. Some administration and backup products can produce exceptions; baseline known maintenance accounts and tooling. - ASPX creation under LAYOUTS is not automatically malicious during legitimate patching or deployment. Correlate with the initiating process, signer/hash, adjacent process execution, and external source IP.
oastify.com, catbox, Wasabi, VS Code, and NetExec have legitimate uses. The combination of a server role, unusual process parent, new destination, or subsequent domain activity provides confidence.- Hunt 7 is intentionally specific to the observed masquerading account. A broader review of all 4732 events is appropriate during incident scoping but noisier.
- SYSVOL script/binary changes may appear only on domain controllers with Defender coverage or detailed object-access telemetry.
dfsrs.exemay not always be captured as the file-creation initiator. - SecurityEvent 4688 can provide a fallback for process execution if Defender tables are unavailable, but useful command-line data requires audit policy and process-command-line collection.